Path: utzoo!utgpu!cs.utexas.edu!wuarchive!uunet!uunet.uu.net From: kyle@uunet.uu.net (Kyle Jones) Newsgroups: alt.sources.d Subject: Re: sux, an enhancer for su Message-ID: <130392@uunet.UU.NET> Date: 25 Apr 91 13:35:57 GMT References: <1991Apr25.024719.4127@convex.com> <462@frcs.UUCP> <7WYA.A2@xds13.ferranti.com> Sender: kyle@uunet.UU.NET Lines: 10 Tom Christiansen writes: > As it is, the program is undesirable from a security standpoint. It would > be less so if the user were at least prompted for his own password. Which kills the basic usefulness of the command! The whole point was to avoid typing a password. The idea behind this easy su seems to be to let the right users _conveniently_ become root, so they can do so often for short periods--- instead of creating one root shell and using it all day, eventually forgetting that they are root and destroying something.